This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

VA Southeast Network (VISN 7)

VISN 07 Decatur, GA

Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on November 28, 2011. Also cited in 225 other reports.


Report ID: SPE000000069072, U.S. Department of Veterans Affairs

Reported Entity: VISN 07 Decatur, GA

Issue:

A contractor (business associate) working in the Fee Basis section at the medical center accessed a patients CPRS records without authorization. the patient called the Aternate PO to complain that her ex-partner told her the contractor looked in the patient record. A sensitive access log was requested to ISO. The log revealed the contractor had accessed the records. The Business Associate has taken disciplanary steps on their employee and the employee was also required to retake VA ISO & VHA Privacy trng courses. Update: 11/28/11:The patient will be sent an offer for credit protection services, since their full SSN was in the record that was accessed.

Outcome:

Individual was provided re-training steps, sanctions were applied to individual, made to retake Privacy trainingCM Ltr sent.

Do you believe your privacy has been violated? Here’s what you can do: